Enterprise-Grade Security

Every action logged. Every permission enforced.

VaultIQ records who did what, to which document, from which IP, and whether it succeeded, on every action in the system. Combine that with database-driven RBAC, MFA, and deployment on your own infrastructure, and your auditors get answers instead of estimates.

AES-256 encryption
Multi-factor auth
LDAP / Active Directory
Air-gapped deployment

Encryption

AES-256 protects documents at rest and TLS 1.2+ secures every connection. Sensitive workflow fields get their own field-level encryption, with derived keys rotated automatically on a 90-day cycle. Passwords are bcrypt-hashed at 12 rounds.

Access Control

Roles and permissions live in the database, not in code. Define your own hierarchy and compose permissions as resource + action (documents:create, workflows:delete). SSO via SAML 2.0 or OpenID Connect, LDAP/Active Directory sync, MFA, per-role IP restrictions, and document-level ACLs.

Audit & Compliance

Every action is logged with timestamp, user, action, resource, client IP, and success or failure. That covers views, edits, downloads, permission changes, and logins. Retention is configurable (365 days by default), and access violations are surfaced in their own queue for review.

Data Protection Requests

Data subject requests are a workflow, not an inbox. A request is submitted against the organisation, listed for the officer who owns it, and closed with a recorded decision. Erasure runs through the deletion-request queue so removal is approved and logged rather than executed on the spot, which is what a regulator asks you to demonstrate under the Kenya Data Protection Act, GDPR and equivalents.

Independent Testing

Enterprise agreements include penetration testing support: you commission the test, against your own deployment, and we support the exercise and the remediation that follows. Because you can self-host, your testers get the real system rather than a shared environment somebody else also has to sign off on.

Data Residency

Choose where your data lives, and whether it leaves your building at all. Store documents on S3, Azure Blob, DigitalOcean Spaces, self-hosted MinIO, or a local filesystem path. On-premise and air-gapped deployments keep every document inside your own network.

Authentication

TOTP-based multi-factor authentication with recoverable backup codes, working with any standard authenticator app. Configurable password policies and session timeouts, JWT sessions with secure signing, and rate limiting on authentication endpoints.

Insider Risk

Custom stamps and watermarks mark documents on release. Denied access attempts land in an access-violations queue, document access history reconstructs exactly who saw what and when, and rate limiting plus security headers cover the perimeter.

Controls, and what they evidence

VaultIQ is the system of record you run your compliance programme on. Below is what it ships and the reviews each control produces evidence for, your certification remains yours to hold.

StandardStatusDetails
GDPRSupportedBuilt-in DPA request handling, configurable retention and disposition, right-to-erasure via the deletion-request queue, and per-tenant data isolation. Self-host to keep all data in your own jurisdiction.
HIPAASupportedTechnical safeguards: AES-256 at rest, TLS 1.2+ in transit, MFA, granular access control, automatic logoff, and an audit trail recording every access to every record.
SOXSupportedSegregation of duties through database-driven RBAC, approval workflows with signature capture, legal holds, and a tamper-evident audit trail with configurable retention.
ISO 27001SupportedAccess control, cryptography, operations security, and logging-and-monitoring controls map to Annex A. Export audit evidence directly from the compliance reporting module.
Records managementSupportedRecords classification, retention schedules, storage tiering, legal holds, a destruction queue with approval gates, and disposition logs that evidence defensible disposal.
Data subject requestsSupportedRequests are submitted, assigned, and closed with a recorded decision. Erasure routes through the deletion-request queue so removal is approved and logged, not executed on the spot.
Independent testingSupportedPenetration testing support is included with enterprise agreements. You commission the test against your own deployment; we support the exercise and the remediation.
Data residencyYour choiceDeploy on-premise or air-gapped and no document ever leaves your network. Cloud deployments run in the region you select, on S3, Azure Blob, DigitalOcean Spaces, or self-hosted MinIO.

Security should never be an afterthought.

Walk through the control set with our team, against your own compliance requirements and your own deployment constraints.